A grounded theory of the role of coordination in software security patch management
Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali Babar
Abstract
Several disastrous security attacks can be attributed to delays in patching software vulnerabilities. While researchers and practitioners have paid significant attention to automate vulnerabilities identification and patch development activities of software security patch management, there has been relatively little effort dedicated to gain an in-depth understanding of the socio-technical aspects, e.g., coordination of interdependent activities of the patching process and patching decisions, that may cause delays in applying security patches. We report on a Grounded Theory study of the role of coordination in security patch management. The reported theory consists of four inter-related dimensions, i.e., causes, breakdowns, constraints, and mechanisms. The theory explains the causes that define the need for coordination among interdependent software/hardware components and multiple stakeholders’ decisions, the constraints that can negatively impact coordination, the breakdowns in coordination, and the potential corrective measures. This study provides potentially useful insights for researchers and practitioners who can carefully consider the needs of and devise suitable solutions for supporting the coordination of interdependencies involved in security patch management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 09fa063f-6ec9-4e72-adfd-59859bef6978Cited by top-tier papers4
- Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare SectorNesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali BabarCSCW 2022 · 18 citations
- Not as easy as just update: Survey of System Administrators and Patching BehavioursAdam D. G. Jenkins, Linsen Liu, Maria K. Wolters, Kami VanieaCHI 2024 · 10 citations
- An Empirical Study of Automation in Software Security Patch ManagementNesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali BabarASE 2022 · 7 citations
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
Builds on4
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Investigating System Operators' Perspective on Security MisconfigurationsConstanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias FiebigCCS 2018 · 116 citations
- Automating Patching of Vulnerable Open-Source Software Versions in Application BinariesRuian Duan, Ashish Bijlani, Yang Ji, Omar Alrawi et al.NDSS 2019 · 63 citations
- A theory of the engagement in open source projects via summer of code programsJefferson De Oliveira Silva, Igor Wiese, Daniel M. Germán, Christoph Treude et al.FSE 2020 · 26 citations
Related papers
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- Speedrunning the Maze: Meeting Regulatory Patching Deadlines in a Large Enterprise EnvironmentGerbrand ten Napel, Michel van Eeten, Simon ParkinS&P 2025
- A Grounded Theory of Coordination in Remote-First and Hybrid Software TeamsRonnie Edson de Souza Santos, Paul RalphICSE 2022 · 55 citations
- The Unpatchables: Why Municipalities Persist in Running Vulnerable HostsAksel Ethembabaoglu, Rolf van Wegberg, Yury Zhauniarovich, Michel van EetenUSENIX Security 2024 · 4 citations
- DISPATCH: Unraveling Security Patches from Entangled Code ChangesShiyu Sun, Yunlong Xing, Xinda Wang, Shu Wang et al.USENIX Security 2025
